freehire launches on Product Hunt on 26 August.

Follow →

Cybersecurity Lead

Summary

Leads Flo Energy’s cybersecurity strategy, governance, and compliance as Senior Security Lead, defining policies, risk frameworks, and cloud security baselines while collaborating with engineering, legal, and business teams to embed security across products and operations.

About Flo Energy

Hi, we are Flo! We are on a mission to switch as many people and businesses as possible to affordable, renewable solutions.

We began in a small shophouse in Singapore and have grown rapidly ever since, expanding into Australia with even bigger plans ahead.

Unlike other retailers, we have built our own best-in-class energy platform entirely in-house. Designed specifically for the sector, it automates complex processes and keeps costs down, letting us offer genuinely affordable products to our customers.

Behind Flo is a diverse team of passionate engineers, data scientists, operators, and energy experts. We come from different backgrounds, but we are united by the shared goal of creating a more sustainable future. If you want to make an impact and help accelerate the renewable energy transition, we would love to meet you.

Find out more about us on https://floenergy.sg/business

About the role

At Flo, security is a shared responsibility. As the Senior Security Lead, you will be responsible for driving Flo's cybersecurity governance, risk management, compliance, and overall security strategy.

You will establish security policies, standards, and governance processes while working closely with Engineering, Infrastructure, Legal, Compliance, and business stakeholders to ensure security is embedded across our people, processes, and technology.

This role is primarily focused on security governance and leadership. While you are not expected to implement every technical security control, you should have a solid understanding of modern security practices and provide governance, oversight, and guidance across cloud security, application security, security operations, and IT initiatives.

As the lead of Flo's Security Guild, you will foster collaboration, provide security guidance, and help teams build and operate secure solutions.

What you'll do:

As the Senior Security Lead, you will be responsible for defining and driving the organisation's cybersecurity strategy while supporting secure business growth and regulatory compliance.

Security Governance & Policy

  • Define and execute Flo's cybersecurity strategy and roadmap.
  • Develop and maintain security policies, standards, and governance frameworks.
  • Develop and maintain Flo's Cloud Security Framework and security baselines to support secure cloud adoption.
  • Own the cybersecurity risk register and conduct security risk assessments.
  • Lead compliance initiatives including ISO 27001, SOC 2, PDPA, and other applicable frameworks.

Security Advisory & Oversight

  • Provide security guidance for projects, cloud environments, applications, and technology initiatives.
  • Promote Secure SDLC, threat modelling, and security best practices across Engineering teams.
  • Provide governance and oversight of security capabilities such as SIEM, EDR/XDR, IAM and MDM.
  • Coordinate incident response activities and support continuous improvement of security controls.

Security Leadership

  • Lead cross-functional security initiatives and projects that improve Flo's overall security posture.
  • Work closely with Engineering and Infrastructure teams to implement security improvements across applications, cloud platforms, infrastructure, and business systems.
  • Identify security gaps and work with Engineering, Infrastructure, and business teams to implement appropriate security improvements.
  • Lead Flo's Security Guild, facilitating security discussions, sharing best practices, and serving as the primary point of contact for security-related guidance.
  • Promote security awareness and foster a strong security culture across the organisation

Security Awareness & Culture

  • Develop and maintain Flo's security awareness programme.
  • Lead security awareness initiatives, phishing simulations, and security training.
  • Promote a strong security culture across the organisation

Third-Party Security

  • Assess the security of new and existing vendors, SaaS platforms, and third-party service
  • providers.
  • Evaluate security risks and provide recommendations during vendor selection.
  • Work with Legal and business stakeholders to address security requirements during vendor engagements.
  • Monitor third-party security risks throughout the vendor lifecycle

Qualifications

  • Bachelorʼs degree in Cybersecurity, Computer Science, Information Security, or a related field.
  • Strong experience in cybersecurity leadership, governance, and risk management.
  • Experience developing cybersecurity strategies, roadmaps, and security programs.
  • Strong understanding of cloud security, application security, and secure architecture principles.
  • Experience with threat modelling, security reviews, vulnerability management, and Secure SDLC.
  • Familiarity with SIEM, EDR, incident response, and security monitoring practices.
  • Experience managing security awareness and phishing simulation programs.
  • Familiarity with compliance frameworks such as ISO 27001, SOC 2, and PDPA.
  • Strong stakeholder management, communication, and influencing skills.
  • Ability to translate technical security risks into business-focused recommendations.
  • Relevant certifications such as CISSP, CISM, CRISC, CCSP, ISO 27001 Lead
  • Implementer/Auditor, or equivalent are advantageous.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available